Nitrokey / dongleauth

List of sites with two factor auth support for OTP and U2F hardware dongles.
https://www.dongleauth.com
MIT License
302 stars 112 forks source link

Websites to include/update in the list #331

Open KNTRO opened 1 year ago

KNTRO commented 1 year ago

These are websites to be included/updated in the list at https://buybitcoinworldwide.com/dongle-auth/

103058167 commented 1 year ago

@KNTRO This repository only looks at dongleauth.com, seems like that site has not been maintained for a while. Seems like some of the update suggestions could be made here on dongleauth.com as well. Happy to submit a PR if you could give me some additional information about the documentation of each sites

KNTRO commented 1 year ago

@103058167 Sure!

I will include documentation for each website, next to its name/URL.

103058167 commented 1 year ago

@KNTRO After having a closer look at the entry suggestions to be included, I can see that firstly the organization which you would like to include some lack documentation to suggest the support of WebAuthn, FIDO2, U2F or multiple dongles. I did some further search into some of the companies above but could find any

codeberg.org (supports both OTP and WebAuthn, FIDO2, U2F and multiple dongles) e.email / murena.io (supports both OTP and WebAuthn, FIDO2, U2F and multiple dongles) simplelogin.io (supports both OTP and WebAuthn, FIDO2, U2F and multiple dongles) WordPress.com (supports both OTP and WebAuthn, FIDO2, U2F and multiple dongles)

Some organization which you wanted to include only had OTP, which I didn't add because dongleauth.com should be more focus on security as apart to just OTP, So I didn't include them

Discogs (supports OTP) AnonAddy.me (supports OTP) Mailo (supports OTP) notabug.org (supports OTP) qiita.com (supports OTP)

As for updates, I will submit a PR of those organization that I could validate to be true and for some of you suggested changes have already been made and I did not touch them (not listed)

accounts.firefox.com (supports OTP) Crowdin (supports OTP) MercadoLibre / Mercado Libre / Mercado Pago (supports OTP) Outlook.com / OneDrive (now it also supports WebAuthn, FIDO2, U2F and multiple dongles) Mastodon (now it also supports WebAuthn, FIDO2, U2F and multiple dongles) Vimeo (supports OTP)

If you do happen to find documentation supporting U2F for the first 4 companies listed, please post them here so I can I have a look at them

JeGr commented 1 year ago

@103058167 If I may add to two of your four companies:

Codeberg: https://docs.codeberg.org/security/2fa/#step-2%3A-navigate-to-the-security-tab-and-click-on-the-enroll-button

The screenshot from step 2 clearly shows the ability to add hardware tokens that have the FIDO U2F standard. I agree the documentation is about TOTP but the screen (and account backend) show the ability to work with that.

As to simplelogin: They were integrated into Proton as part of Proton Mail. They can still function and have accounts not linked to proton, but have the same backend base now, so support TOTP and FIDO/U2F:

image

image

I also wanted to add, that as the list already has entries with TOTP only that others supporting OTP should perhaps be considered.

And last, I checked the list and found a few entries wrong that nowadays support at least OTP or more. Nintendo Account/Network or Playstation Network are two of them, that jump to my mind, as PSN for example enforces/strongly encourages the use of 2FA via OTP at least when setting up a PS5 and after the Nintendo Account problems with older devices (DS/3DS etc) they also enabled 2FA for their Nintendo Account for all newer devices (e.g. Switch, eStore etc.) that are now OTP backed. Ubisoft Connect (no longer Uplay) also supports OTP 2FA for at least a few years now.

Cheers :)

103058167 commented 1 year ago

@JeGr Will create a PR for the first two entries discuss, and will update Nintendo and Playstation companies in the near future.

dayoko-online-planner commented 11 months ago

Great project. Please add Dayoko to your task management applications. We will implement it soon. https://dayoko.com